References https://www.twcert.org.tw/en/cp-139-7870-befb5-2.html https://localh0st.run/post/asus-downloadmaster-2/ https://nvd.nist.gov/vuln/detail/CVE-2024-31163 https://www.asus.com/security-advisory/ https://starlabs.sg/blog/2020/08-asuswrt-url-processing-stack-buffer-overflow/ https://www.exploit-db.com/exploits/31033 https://github.com/advisories/GHSA-m4f9-32gh-9xh6
Related VulnerabilitiesPoCCVE-2026-81199: MasterStudy LMS < 3.7.46 - Unauthenticated Student Statistics Disclosure上海小羚羊软件股份有限公司小羚羊ERP系统downloadView存在任意文件读取漏洞仁和兴业(深圳)软件有限公司仁和云ERP attachmentdownloadAttachment 接口存在任意文件读取漏洞PoCCVE-2019-11043: PHP-FPM Path Info Buffer Underflow - Remote Code Execution玉帛软件仓库管理系统DownloadFile存在任意文件读取漏洞安科瑞EMS企业微电网能效管理平台 /SubstationWEBV2/main/appDownload 文件读取漏洞云连ERP管理系统 /gateway/download!download.action 代码执行漏洞泛微 e-cology10 /papi/em/transform/downLoadSyslog 文件读取漏洞PoCCVE-2026-8037: Progress ADC LoadMaster - Command Injection方向标邮件网关 /common/cgi/download.cgi 代码执行漏洞MasterStudy LMS /wp-admin/admin-ajax.php?action=stm_lms_load_content 文件包含漏洞(CVE-2024-3136)Progress Kemp LoadMaster /accessv2 命令执行漏洞(CVE-2026-8037)通天星CMSV6车载视频监控平台 /808gps/StandardLoginAction_downLoad.action 文件读取漏洞